header-logo
Suggest Exploit
vendor:
VU Web Visitor Analyst
by:
L0rd CrusAd3r
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: VU Web Visitor Analyst
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

VU Web Visitor Analyst Authentication Bypass

VU Web Visitor Analyst is an application that retrieves website visitors’ IP address, visited date and time, visited page name, their country, and their ISP. An authentication bypass vulnerability exists in the application, which allows an attacker to bypass authentication and gain access to the application.

Mitigation:

Ensure that authentication is properly implemented and enforced.
Source

Exploit-DB raw data:

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0     _                   __           __       __                     1
1   /' \            __  /'__`\        /\ \__  /'__`\                   0
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0
0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0
0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
1                  \ \____/ >> Exploit database separated by exploit   0
0                   \/___/          type (local, remote, DoS, etc.)    1
1                                                                      1
0  [+] Site            : Inj3ct0r.com                                  0
1  [+] Support e-mail  : submit[at]inj3ct0r.com                        1
0                                                                      0
1                    ###########################################       1
0                    I'm L0rd CrusAd3r member from Inj3ct0r Team       1
1                    ###########################################       0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

Author: L0rd CrusAd3r aka VSN [crusader_hmg@yahoo.com]
Exploit Title:VU Web Visitor Analyst Authentication Bypass
Code: ASP 3.0 & VBScript
Vendor url:http://www.vunet.us
Version:n/a
Price:80$
Published: 2010-06-12
Greetz to:Sid3^effects, MaYur, M4n0j, Dark Blue, S1ayer,d3c0d3r,KD and to
all ICW members.
Spl Greetz to:inj3ct0r.com Team

#####################################################################################################################################################################################################

Description:

VU Web Visitor Analyst is an application that retrieves your website
visitors’ IP address, visited date and time, visited page name, the link a
visitor came from originally (referred URL address). You can view the single
visitor history with the list of all pages visited. You can also display
visits by date criteria. The weekly statistics allow you to see the total
visits for every single day in the present and last weeks. The monthly
statistics allow you viewing the total visits of every month for the whole
year. In addition, every visitor is linked to the web database containing
personal information about this visitor’s IP address (such as name, address,
phone, email, etc. if available).
Pleasant and professional graphic user interface will make your statistical
experience more enjoyable.

#######################################################################################################################################################################################################

Vulnerability:

*Authentication Bypass found

The Provided Script as Sqli Vulnerability in Admin Login page


DEMO URL:

http://[site]/demo/webanalyst/default.asp

Use the string a' or '1'='1 for Username and Password to gain access.


# 0day n0 m0re #
# L0rd CrusAd3r #

-- 
With R3gards,
L0rd CrusAd3r